Splunk Enterprise

Error message on Splunk

hordoffa1970
New Member

Encountered the following error while trying to save: Failed to create. Configuration for port 9997 already exists. I am getting this message on Splunk when I try to configure and save the listening port

Labels (1)
0 Karma

kknairr
Contributor

@hordoffa1970 The error message “Failed to create. Configuration for port 9997 already exists” means the receiving port you’re trying to configure is already set up somewhere in your Splunk configuration. Port 9997 is the default receiving port for Splunk indexers, so if it’s already enabled, trying to add it again will trigger this message.

You can check existing receiving configuration In Splunk Web by navigating to: 
Settings → Forwarding and Receiving → Configure Receiving

You should see port 9997 already listed. If 9997 is already active, you don’t need to add it again. Just confirm it’s listening.

> Giving Karma & Marking the answer helps others find solutions faster!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @hordoffa1970 

As the error suggests, it looks like something is already listening on port 9997. 

What exactly is it you are trying to do? Do you already have an inputs.conf configured to receive data (or is something else on your system using port 9997)?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...